Breaking
SecurityConfirmed

Windows Patch Tuesday Surges Past 964 Fixes With Zero-Days

Microsoft's September release tops 964 fixes, including two exploited zero-days and a wormable DNS flaw.

··1 hour ago·7 min read
A security and privacy dashboard with its status
Photo by Zulfugar Karimov on Unsplash

Microsoft's September Patch Tuesday release is here, and it's a hefty one — 964 vulnerabilities addressed, with two zero-days already under active attack and a DNS flaw that could reignite fears of a worm. The sheer scale of the update, another record since the company leaned on AI to accelerate bug hunting, is forcing security teams to rethink how they prioritize patches.

Record Patch Count Stuns Experts

The 964 vulnerabilities in this month's release mark another high-water mark for Microsoft, which began integrating AI into its vulnerability discovery process earlier this year. This count excludes 174 third-party and open-source CVEs, 23 Chromium/Edge CVEs, and nine Microsoft-mitigated vulnerabilities in applications like Azure, Entra, and Copilot Studio where no customer action is required.

The number caught some longtime observers off guard. Dustin Childs, head of threat awareness at the Zero Day Initiative, couldn't help but reference a classic film when contemplating the scale. “Looking at nearly 1,000 vulnerabilities in a single month, all I can think is: ‘My God, it’s full of stars,'” he said.

Childs didn't stop there. “AI-assisted bug discovery has exploded patch counts into a whole new galaxy, and defenders simply have to embrace the suck,” he added, highlighting the growing burden on IT teams.

Two Zero-Days Demand Immediate Action

The two zero-day vulnerabilities revealed today require urgent attention. The first, CVE-2026-85880, is a heap-based buffer overflow in Windows ALPC (Advanced Local Procedure Call), a core inter-process messaging system. Microsoft reports that this vulnerability is already being exploited. An attacker with code execution in a low-privilege AppContainer could exploit it locally to escape the sandbox and elevate privileges. No user interaction is needed, according to Action1. Affected products include certain versions of Windows Server 2012, Windows Server 2016, and Windows 10 Desktop. Chris Goettl, Ivanti's vice-president of product management, noted that this vulnerability “affects the entire Windows fleet.”

The second zero-day, CVE-2026-81963, is an elevation of privilege flaw stemming from improper link resolution before file access, also known as link following, in the Windows Update Stack. Successful exploitation could let an attacker gain System privileges. Microsoft lists affected versions including Windows 11 Desktop and Windows Server 2025, though researchers at Action1 caution that specific affected Windows versions cannot be confirmed from available data. There is no workaround other than installing the fix, and with exploitation already detected, remediation is a high priority, even though the severity and CVSS score cannot be confirmed. This marks the first zero-day among seven privilege escalation flaws discovered in the Windows Update Stack since 2022, and the first to be exploited, according to Satnam Narang, senior staff research engineer at Tenable.

Wormable Threats Loom

Beyond the zero-days, roughly 20 of the patched vulnerabilities could be wormable, Childs warned. “We haven’t seen a global worm in years, but with a DNS flaw acting as the spiritual successor to SigRed, that reality could change fast,” he said.

That DNS flaw is CVE-2026-69730, a Windows DNS remote code execution vulnerability. As of Tuesday, it had not yet been exploited, but Microsoft expects it will be. An unauthenticated attacker could exploit it by sending a specially crafted packet to an affected service over the network, potentially executing code on the target system without any authentication or user interaction.

Jack Bicer, Action1's director of vulnerability research, pointed to other remote code execution flaws that could spread quickly across networks if left unpatched. He highlighted CVE-2026-62893, a Windows Deployment Services TFTP Server issue first patched in August, and CVE-2026-69590, a Windows Routing and Remote Access Service flaw. Both require no authentication or user interaction, making them candidates for rapid propagation.

Prioritization Over Numbers

Tyler Reguly, Fortra's associate director of security R&D, argues that as Microsoft plays catch-up on patching, raw vulnerability counts have lost meaning. “This is not a Microsoft-specific problem,” he noted. “We see the same issue with Oracle and other large vendors that are being proactive. We need to remember that these large CVE counts are a good thing, as we’re reducing attack surface before attackers get a chance to find and utilize the vulnerabilities. Eventually, all those long-standing, hard to find vulnerabilities will be fixed, and Patch Tuesday will return to its typical cadence. Until that happens, prioritization is key, and gift cards for extra coffee for your admins would likely be appreciated.”

Bicer emphasized that the scale of this month's releases requires security leaders to move beyond CVSS-driven patching. He advises prioritizing systems based on exploitability, network exposure, privilege requirements, business criticality, and the consequences of compromise. The most consequential risks, he said, are concentrated in remotely reachable infrastructure, identity and authentication services, database platforms, virtualization environments, and Windows components where successful exploitation could provide code execution or elevated privileges.

“One of the most important things to recognize across the recent rise in Patch Tuesday releases is that while the number of vulnerabilities being patched is rising, the number of vulnerabilities that can and will affect most organizations remains quite low. AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles. It’s critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context.”

— Jack Bicer, director of vulnerability research at Action1

Beyond Microsoft: Other Vendor Patches

Microsoft wasn't the only vendor shipping critical fixes this week. Researchers at Nightwing noted that Adobe patched an actively exploited zero-day in Adobe Commerce and Magento (CVE-2026-75650, CVSS 10.0), dubbed StyleSmuggler, which drops Linux backdoors and web shells. Adobe has declared that “Urgent Action” is required.

Fortinet confirmed ongoing active exploitation of two older authentication bypass vulnerabilities in FortiOS (CVE-2024-55591 and CVE-2025-24472), which allow unauthenticated remote attackers to seize administrative control of edge firewalls.

Cisco Systems addressed eight serious vulnerabilities across IOS XR systems while warning of active exploitation targeting an unauthenticated denial-of-service flaw in Secure Firewall ASA devices (CVE-2026-20349), first described last month.

Red Hat fixed a critical privilege escalation vulnerability in Advanced Cluster Management for Kubernetes 2 (CVE-2026-10090, CVSS 9.0) that enables attackers to breach multi-tenant container boundaries. Tenable resolved a critical flaw in Sensor Proxy (CVE-2026-18667, CVSS 9.6) that had permitted code execution with elevated privileges.

SAP's Unusually Concentrated Risk

SAP also issued several critical security notes this month. Jonathan Stross, Pathlock’s senior product manager for cybersecurity R&I, observed that three of the Security Notes reach full compromise territory without a single valid credential. “That is an unusually concentrated cluster of unauthenticated, network-reachable, maximum-impact issues for a single Patch Day,” he said.

The most critical is SAP Security Note #3747649, addressing a memory corruption vulnerability in the Extended Passport Processing (EPP) component in ABAP-based systems. Discovered by Onapsis Research Labs and dubbed OVERPASS, this flaw allows an unauthenticated attacker to send crafted network requests with a malformed EPP header, causing undefined behavior and abnormal program termination. The patch covers ABAP and Java kernels and SAP Web Dispatcher version 9.16; other Web Dispatcher versions and those in SAP S/4HANA Extended Application Services are not affected.

Onapsis urged immediate patching, noting the vulnerability exists by default in a wide range of SAP components, is remotely exploitable without authentication, and allows attackers to run arbitrary OS commands on the SAP host with administrative privileges. This leads to full compromise of underlying business data and processes. The flaw is reachable through several components and communication protocols, and since no credentials are required, no single network control can fully mitigate risk.

Another note, #3759472, addresses a CVSS 9.8 vulnerability in NetWeaver Message Server. This bug results from insufficient validation of the authenticity of internal application server components during registration. Unauthenticated attackers with network access could register unauthorized components and perform unauthorized actions. Dubbed S4GET by Onapsis Research Labs, the vulnerability affects SAP’s entire modern kernel family (9.16, 9.18, 9.19, 9.20), meaning every S/4HANA 2025 system and earlier releases already moved to those kernels are exposed.

Why This Patch Tuesday Matters

The record-breaking volume of fixes is more than a logistical headache — it's a signal that AI-driven vulnerability discovery is fundamentally changing the patching landscape. For security teams, the takeaway is clear: with hundreds of new CVEs landing each month, treating every patch equally is no longer viable.

This month's update underscores the importance of focusing on what's actually exploitable and exposed in your environment. The presence of two actively exploited zero-days and a DNS flaw with worm potential raises the stakes for rapid prioritization. The concentration of unauthenticated, maximum-impact issues in SAP systems, alongside similar trends from other vendors, suggests that attackers are increasingly targeting internet-facing services without needing valid credentials.

For organizations, the practical response is to triage based on risk context — isolating remotely reachable systems, applying fixes to known-exploited flaws first, and ensuring that business-critical infrastructure isn't left vulnerable while hundreds of other patches wait in the queue. Until the patch cadence stabilizes, proactive prioritization remains the best defense.

#patch tuesday#microsoft#zero-day#windows#vulnerabilities#sap

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories